HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICAUTHENTICATIONHighContained
Central Valley Regional Center
bd_29ab4518a5c95a5a · schema v1 · pii pii-v1
Full breach record for Central Valley Regional Center →Central Valley Regional Center (CVRC) reported a data security incident in California where an unauthorized third party accessed an employee's email account between July 25 and August 2, 2019. The breach exposed personal information of 11,990 California residents, including names, SSNs, driver's license numbers, Medi-Cal numbers, and financial account data. CVRC disabled access, engaged forensic investigators, notified the FBI, and provided 12 months of complimentary credit monitoring to affected individuals.
California clockDiscovered Jul 29, 2019 → Notified Oct 18, 201981d ✗ CA 60-day late12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_da5a182176d08e42Montana State AGfiled 2019-10-18(6d gap)Verified
- bd_1b96bb4bf5e1aaadHHS OCRfiled 2019-10-11(13d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-183781
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 24, 2019
- Raw hash
- f9297db5de250ee9bec07885e2fbcd384f536bb568a9622f6cca3325a1f97258
Reporting entity
- Name
- Central Valley Regional Centernorm: central valley regional center
Victim entity
- Name
- Central Valley Regional Centernorm: central valley regional center
Incident
- Discovered
- Jul 29, 2019
- Materiality determined
- Oct 24, 2019
- Notification sent
- Oct 18, 2019
- Affected individuals
- 11,990
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICAUTHENTICATION
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified California Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(87 days from discovery to filing)
- Compliance flags
- CA 60-day late · 81d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 29, 2019→ Notified: Oct 18, 201981d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.